Job-Nr. 48074072
IG

Working Student / Intern: Offensive Security Engineer (Red Team & AppSec) (f/m/x)

iLert GmbH vor 4 Tagen
TeilzeitWerkstudentHybrid
StandortKöln, Nordrhein-Westfalen

We hire for talent and a builder's mentality, not a checklist. If you have a writeup, a CTF profile, a disclosed vulnerability, or a tool you built — bring it. That tells us more than any certification will.

Attack Our Product: Pentest the ilert platform end to end — web app, public API, webhooks, and integrations. Hunt for what actually matters in multi-tenant SaaS: broken auth and authz, tenant isolation failures, IDOR, SSRF, injection, and abuse of our alerting and escalation logic.

  • Red Team Our Infrastructure: Probe our cloud and Kubernetes configuration, secrets handling, CI/CD pipelines, and software supply chain. Find the path from "small misconfiguration" to "real access."
  • Run Authorized Social Engineering: Design and run phishing and pretexting exercises against our own team — always under a written scope signed off by the CTO before you start, always debriefed as a learning exercise, never punitive. Then help us fix what the exercise exposed.
  • Break the AI, Too: We're building an AI SRE that investigates incidents and can execute actions on approval. Prompt injection, tool abuse, and agent-boundary testing are wide-open ground here — and largely unexplored.
  • Harden the SDLC: Bring dependency, secrets, and static analysis into CI where it earns its place. Threat-model new features with the engineers building them. Review the security-relevant PRs.
  • Write Findings People Can Act On: A reproducible proof of concept, an honest severity call, and a concrete fix — then pair with the engineer who ships it. We care as much about closing the gap as finding it.

Current Student: Enrolled in Computer Science, IT Security, Informatics, or a related technical field.

  • Demonstrable Offensive Work: Not coursework or certificates — things you've actually done. CTF results, HackTheBox/TryHackMe progression, bug bounty reports, a home lab you built, a writeup you published, a CVE you found. Show us one and walk us through it.
  • You Can Read and Write Code: Enough to navigate a real codebase (we run Java, Rust, TypeScript/React), understand why a bug exists, and propose the fix — not just report that a scanner flagged something.
  • Web Security Fundamentals: OWASP Top 10 as a working tool, not a memorized list. Authentication and session handling, access control, injection classes, SSRF, and what makes multi-tenancy hard.
  • Comfortable With the Tooling: Burp Suite or equivalent, plus the usual recon and exploitation kit — and the judgment to know when manual beats automated.
  • Judgment and Discretion: This role comes with access and trust. You stay inside the agreed scope, you don't test things you weren't authorized to test, and you handle what you find responsibly. Non-negotiable.
  • Language: Fluent English (our working language).

Cloud or Kubernetes security, Infrastructure-as-Code scanning

  • CI/CD and supply chain security (SAST, DAST, SCA, SBOM)
  • LLM and agent security — prompt injection, tool-use boundaries, agent sandboxing
  • Detection engineering: not just getting in, but noticing when someone else does
  • German language skills
  • A published CVE, security blog, meetup talk, or open source security tooling

Benefits

Cologne, Germany (Hybrid) Team: Engineering · Reports to: CTO · Format: Working Student (16–20h/week) or Internship (3–6 months) Location: Able to be in our Cologne office regularly — the role is hybrid, not remote. Bonus points

  • A Real Attack Surface: Not a lab, not a CTF box. Production software that companies worldwide depend on during their worst moments.
  • Build the Practice: You're the first security hire. What offensive security looks like at ilert is genuinely yours to define — with the CTO in your corner.
  • Unexplored Ground: Agentic AI security is barely a discipline yet. You'd be doing original work on it, on a product that's actually shipping.
  • Hybrid Freedom: Our office in Cologne Rheinauhafen (3 days/week) plus work from home (2 days/week).
  • Student-Centric: Flexible hours around lectures and exam periods.
  • Direct Mentorship: You report to the CTO and work alongside experienced engineers who want to be shown where they got it wrong.
  • Focus Culture: We protect maker time, favor async, and keep meetings rare.

Keywords: Werkstudent IT-Security, Penetration Testing, Praktikum Cyber Security, Red Team, Application Security, Köln.

Über den Arbeitgeber

IG
iLert GmbH
Unternehmen · Köln
1
offene Stellen
Alle Stellen des Arbeitgebers